Skip to content

We find the gaps.Then we watch them.

We test your defences the way a real attacker would, then put an AI analyst on your endpoints to catch what comes next — reasoning through every alert and holding for a human before anything irreversible. All EU-hosted, on the model you choose.

Trusted by security and engineering teams across the Nordics

  • Vickers
  • CleanConsulting
  • Vickers
  • CleanConsulting
  • Vickers
  • CleanConsulting
  • Vickers
  • CleanConsulting

What's at stake

None of this is hypothetical.

Four of the six below are documented incidents you can look up. Two are patterns — written as patterns, because we will not dress an anecdote up as a case study.

01

Financial impact

What if ransomware locks our systems?

In July 2021 ransomware reached one of Coop Sweden's software suppliers and around 800 stores closed. The tills could not take payment, so the business stopped — and stayed stopped until the systems were rebuilt.

02

Fraud

What if someone impersonates the CEO by email?

Business email compromise does not look like an attack. Someone who has read enough of your mail knows the nickname the CEO signs off with, which supplier is due to be paid, and when the CFO is travelling. The payment clears before anyone thinks to check.

03

Client trust

What if the client list leaks?

A leaked client list is not one incident. It is every client relationship at once, and someone has to ring each of them and explain. Every one of those calls is a conversation about whether they stay.

04

Availability

What if the payment rails go down?

Through spring 2025 both BankID and Swish were repeatedly knocked over by denial-of-service attacks, disruption the Riksbank recorded in its own payments reporting. Neither service was breached. They were merely unavailable — which, for a day, is the same thing.

05

Deepfake fraud

What if the person on the video call isn't real?

In 2024 an employee at the engineering firm Arup joined a video call with the CFO and several colleagues and authorised fifteen transfers worth about $25 million in a single day. Every face and voice on that call had been generated from public footage.

06

False confidence

What if the tool everyone trusts can be bypassed?

Exam-monitoring software mandated across more than 200 Danish institutions could be defeated by renaming the browser executable. A control being installed, paid for and reported on says nothing about whether it holds.

One of us found that one

The analyst desk

Every verdict arrives with its reasoning attached

A severity score tells you nothing you can act on. Cryvanta shows the events it correlated, the case it built, what it did — and exactly where it stopped and waited for a human.

Verdict recordWKS-0413 · 09:41 CET

Evidence

  • 09:41:02process.createwinword.exe → powershell
  • 09:41:02net.connect185.104.· · ·:443
  • 09:41:03file.write%TEMP%\up1.dat
  • 09:41:03registry.set…\Run\OneDriveSyncer
  • 09:41:04process.createrundll32.exe up1.dat
Detection

PowerShell download cradle

T1059.001

Analyst reasoning

  • Correlated 5 events on WKS-0413 within 2s
  • Parent chain matches T1059.001 download cradle
  • No change ticket, no maintenance window
  • Host holds finance shares — blast radius high
VerdictTrue positive · host isolated
Disk wipe requires human approval — held
Illustrative record · not live data

The closed loop

Every attack we run teaches your defence to catch the next one

Offence informs defence. When our pentest fires a technique, the detection side learns to catch it — and every rule it produces is compile-checked and reviewed before it goes live.

  1. 01

    Attack

    Our pentest runs a real technique against your estate, under a scope you signed.

  2. 02

    Observe

    The endpoint sensor captures the telemetry the technique leaves behind, as normalised OCSF events.

  3. 03

    Detect

    The same Sigma engine runs on the endpoint and in the cloud, so rule semantics never drift between the two.

  4. 04

    Reason

    The AI analyst weighs the evidence and returns a verdict with its rationale, confidence and suggested action.

  5. 05

    Harden

    A new rule is drafted from the cluster, compile-checked, and queued for an operator to accept or reject.

Watch it

The whole loop, in thirty seconds

Then it starts again — and irreversible actions still hold for a human, by default.

Thirty seconds, no sound. The five stages above, in the order they actually run.

An attacker only has to find one way through. Everything we learn finding it becomes something your defence already knows.

EU sovereignty

Your defence, kept in Europe

Regulation is moving fast, and most security stacks still route through US clouds and US models. Cryvanta is built the other way around.

NIS2

Scoped for the essential- and important-entity obligations landing across the EU.

DORA

Operational-resilience testing and monitoring for financial entities and their ICT providers.

GDPR & residency

Data stays in the EU. Erasure and retention controls are part of the platform, not paperwork.

Bring your own model

Point the analyst at an EU-hosted model — your sovereignty requirements, your choice.

Cryvanta is building toward SOC 2 and formal certification — we'll publish status rather than badges we haven't earned.

How we start

The first thing we do is talk.

No scope, no deck, no proposal. Half an hour on what you actually run and what is keeping you up — then we tell you what we would do about it, including if the answer is nothing yet.

01

A 30-minute call

What your estate actually looks like, what is already in place, and what is worrying you. Nothing to prepare and nothing to install.

02

We say what we'd do

And what we wouldn't. If a pentest is not the right first move for you, we will say so — it is a short conversation either way.

03

A written scope

Nothing is touched, tested or deployed until you have agreed the targets, the rules of engagement and the timing in writing.

04

The work, then a debrief

A prioritised report your engineers can act on and your board can read, walked through live rather than emailed over.

Who you'll be talking to

The people on the call are the people doing the work

No sales layer between the first conversation and the founders and delivery team closest to the work.

Robin Österdal, Founder & CEO

Offence

Robin Österdal

Founder & CEO

Leads the pentest work. Thinks like an attacker and explains the result without hiding behind a scanner report.

Malthe Bang Norengaard, Co-founder & CTO

Defence

Malthe Bang Norengaard

Co-founder & CTO

Builds the technology — the endpoint sensor, the detection pipeline, the AI analyst, and the platform underneath them.

Henrik Andersson, Board member · Company & Customer Delivery

Board

Henrik Andersson

Board member · Company & Customer Delivery

Nearly 30 years in Swedish IT consulting — took a data and analytics firm from its founding year through to acquisition.

Where we actually are

Everything here is either shipping or labelled

Most security vendors round up. We don't — in security, being caught overstating costs more than the feature was worth. What is live is genuinely live and running against real estates; what is ahead is marked ahead. You will never have to guess which.

Capability

4 live · 4 ahead

  • PenTest engagements for EU / Nordic organisationsLive
  • Windows endpoint sensor + cloud detection pipelineLive
  • AI analyst: triage, investigation and verdictsLive
  • Multi-tenant console, GDPR erasure & retentionLive
  • macOS and Linux endpoint sensorsAhead
  • General availability beyond design partnersAhead
  • SOC 2 and independent certificationAhead
  • Self-service tenant onboardingAhead

Find the gaps, then watch them

Start with half an hour on what you actually run. From there it might be a pentest, the AI SOC early-access programme, or nothing yet — we will tell you which. A real person replies.